Skip to content

[Snyk] Upgrade express from 4.18.1 to 4.21.0 - #25

Open
X-oss-byte wants to merge 1 commit into
mainfrom
snyk-upgrade-1aa8bf3c9d3657851b04a2bf02868401
Open

[Snyk] Upgrade express from 4.18.1 to 4.21.0#25
X-oss-byte wants to merge 1 commit into
mainfrom
snyk-upgrade-1aa8bf3c9d3657851b04a2bf02868401

Conversation

@X-oss-byte

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to upgrade express from 4.18.1 to 4.21.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 7 versions ahead of your current version.

  • The recommended version was released on 22 days ago.

Issues fixed by the recommended upgrade:

IssueScoreExploit Maturity
high severityAsymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
624No Known Exploit
medium severityOpen Redirect
SNYK-JS-EXPRESS-6474509
624No Known Exploit
medium severityCross-site Scripting
SNYK-JS-EXPRESS-7926867
624No Known Exploit
medium severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
624Proof of Concept
low severityCross-site Scripting
SNYK-JS-SEND-7926862
624No Known Exploit
low severityCross-site Scripting
SNYK-JS-SERVESTATIC-7926865
624No Known Exploit
Release notes
Package name: express from express GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade express from 4.18.1 to 4.21.0.
See this package in npm:
express
See this project in Snyk:
https://app.snyk.io/org/sammytezzy/project/20d96395-553d-4f02-9cf2-7a7ac30390c2?utm_source=github&utm_medium=referral&page=upgrade-pr
@bolt-new-by-stackblitz

Copy link
Copy Markdown

Review PR in StackBlitz CodeflowRun & review this pull request in StackBlitz Codeflow.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: dd85aaf

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. Here's why:

  • It seems to have been created by a bot ('[Snyk]' found in title). We assume it knows what it's doing!
  • We don't review packaging changes - Let us know if you'd like us to change this.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@X-oss-byte@snyk-bot